But I thought there were no viruses or malware on Linux! For example: https://www.howtogeek.com/135392/htg-explains-why-you-dont-n...
Free Download Manager backdoored – a possible supply chain attack on Linux
21–30 of 143 posts
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#22How is this a supply chain attack? My official debian repository have never been breached so far.
This is no different from downloading an .exe off a shady website and blindly running the .exe.
Also: https://packages.debian.org/search?keywords=download+manager... lists:
• uget: https://sourceforge.net/projects/urlget/
• kget: https://apps.kde.org/en-gb/kget/
• persepolis: https://persepolisdm.github.io/
why use "Free Download Manager" when high quality ones are already officially packaged by debian? Is this targeting new-comers from windows?
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#23Why would you use a "Free Download Manager" when wget is right there? Or a web browser, such as Firefox? Or torrent clients to deal with large Linux ISO downloads? Or the various storefronts, like Steam? Or your own distro's package manager? This wasn't packaged on any distro, so this isn't even a meaningful attack: Users had to go out of their way to install it from a foreign source. This is no different than if you…
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#24This is one more reason to run every program in a sandbox rather than with full privileges.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#25Who uses a download manager in the days of high speed internet access and, in general, cloud services?
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#26This is one more reason to run every program in a sandbox rather than with full privileges.
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#27Who uses a download manager in the days of high speed internet access and, in general, cloud services?
I'm trying to imagine the kind of user that's both able to blindly install a random .deb downloaded from a website, while also being willing to do so. Linux geeks with no sense of danger on the internet?
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#28This is installed by adding a shady repository to your apt sources.list... How is this a supply chain attack? My official debian repository have never been breached so far. This is no different from downloading an .exe off a shady website and blindly running the .exe. Also: https://packages.debian.org/search?keywords=download+manager... lists: • uget: https://sourceforge.net/projects/urlget/ • kget: https://apps.kde.…
How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#29Re: Free Download Manager backdoored – a possible supply chain attack on Linux
#30Who uses a download manager in the days of high speed internet access and, in general, cloud services?
Happy FileZilla user here, on my FreeBSD laptop. I move tons of files from remote astronomical observatory routinely, sometimes need to define custom rules - what to download, upload, filter across folders, etc. Sometimes I need to push a file from very low data-rate link from somewhere in the middle of nowhere to the observatory, sometimes over a satellite link. Sometimes I want a throttled download of a large queue…
But I suppose you're probably talking about devices that only know about internet protocols before 1991....